< Back to all clusters
[TECHNOLOGY] · 4 sources

started · updated

Shai-Hulud malware resurfaces via npm and GitHub Actions

A new wave of the Shai-Hulud malware has been identified, impacting the software supply chain through the npm registry and GitHub Actions. The malware has affected more than 400 packages across 1,700 versions, specifically targeting widely used caching libraries such as keyv and cacheable.

Security researchers at Socket reported that two previously disabled GitHub Actions, 'actions-cool/issues-helper' and 'actions-cool/maintain-one-comment', were briefly re-enabled on September 16, 2026. Because the malicious release tags had not been cleaned up, any workflows referencing these actions automatically resumed executing the payload. This allowed the malware to continue harvesting sensitive credentials from CI/CD pipelines, cloud services, Kubernetes, and Vault.

GitHub has since re-disabled the affected repositories as of September 25, 2026. Experts advise developers to rotate secrets, audit upstream references, and switch to commit-specific SHA pinning to mitigate risks from mutable tags.

Entities

GitHub · JFrog · Mini Shai-Hulud · Shai-Hulud · Socket · npm

Claims

What the coverage asserts, and how many sources carry each claim.

  • [● 3 SOURCES] The GitHub Actions 'actions-cool/issues-helper' and 'actions-cool/maintain-one-comment' were compromised. cybernoz.com · www.it-boltwise.de · dev.to
  • [● 3 SOURCES] The release tags for the repositories were not cleaned up, allowing malicious code to execute upon re-enabling. cybernoz.com · www.it-boltwise.de · dev.to
  • [○ 1 SOURCE] A new variant of the Shai-Hulud malware has been identified spreading via the npm registry. b2b-cyber-security.de
  • [○ 1 SOURCE] The malware affects more than 400 packages across over 1,700 versions. b2b-cyber-security.de
  • [○ 1 SOURCE] GitHub disabled the compromised repositories again on September 25, 2026. dev.to
  • [● 2 SOURCES] The compromised GitHub Action repositories became accessible again on September 16, 2026. cybernoz.com · dev.to
  • [○ 1 SOURCE] The malware targets credentials from local environments, CI systems, cloud services, Kubernetes, and Vault. b2b-cyber-security.de